CVE-2026-2913

Source
https://cve.org/CVERecord?id=CVE-2026-2913
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-2913.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-2913
Downstream
Related
Published
2026-02-22T04:02:13Z
Modified
2026-08-12T15:32:15Z
Severity
  • 1.1 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
libvips source.c vips_source_read_to_memory heap-based overflow
Details

A vulnerability was determined in libvips up to 8.19.0. The affected element is the function vips_source_read_to_memory of the file libvips/iofuncs/source.c. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on the local host. The attack's complexity is rated as high. The exploitability is described as difficult. The exploit has been publicly disclosed and may be utilized. Patch name: a56feecbe9ed66521d9647ec9fbcd2546eccd7ee. Applying a patch is the recommended action to fix this issue. The confirmation of the bugfix mentions: "[T]he impact of this is negligible, since this only affects custom seekable sources larger than 4 GiB (and the crash occurs in user code rather than libvips itself)."

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-119",
        "CWE-122"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/2xxx/CVE-2026-2913.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "8.0"
                },
                {
                    "last_affected": "8.0"
                },
                {
                    "introduced": "8.2"
                },
                {
                    "last_affected": "8.2"
                },
                {
                    "introduced": "8.4"
                },
                {
                    "last_affected": "8.4"
                },
                {
                    "introduced": "8.5"
                },
                {
                    "last_affected": "8.5"
                },
                {
                    "introduced": "8.19.0"
                },
                {
                    "last_affected": "8.19.0"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/libvips/libvips

Affected ranges

Type
GIT
Repo
https://github.com/libvips/libvips
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "8.1"
        },
        {
            "last_affected": "8.1"
        },
        {
            "introduced": "8.3"
        },
        {
            "last_affected": "8.3"
        },
        {
            "introduced": "8.6"
        },
        {
            "last_affected": "8.6"
        },
        {
            "introduced": "8.7"
        },
        {
            "last_affected": "8.7"
        },
        {
            "introduced": "8.8"
        },
        {
            "last_affected": "8.8"
        },
        {
            "introduced": "8.9"
        },
        {
            "last_affected": "8.9"
        },
        {
            "introduced": "8.10"
        },
        {
            "last_affected": "8.10"
        },
        {
            "introduced": "8.11"
        },
        {
            "last_affected": "8.11"
        },
        {
            "introduced": "8.12"
        },
        {
            "last_affected": "8.12"
        },
        {
            "introduced": "8.13"
        },
        {
            "last_affected": "8.13"
        },
        {
            "introduced": "8.14"
        },
        {
            "last_affected": "8.14"
        },
        {
            "introduced": "8.15"
        },
        {
            "last_affected": "8.15"
        },
        {
            "introduced": "8.16"
        },
        {
            "last_affected": "8.16"
        },
        {
            "introduced": "8.17"
        },
        {
            "last_affected": "8.17"
        },
        {
            "introduced": "8.18"
        },
        {
            "last_affected": "8.18"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

8.*
8.1
8.10
8.11
8.12
8.13
8.14
8.15
8.16
8.17
8.18
8.3
8.6
8.7
8.8
8.9
v8.*
v8.1
v8.10.0
v8.10.0-beta1
v8.10.0-beta2
v8.10.0-rc1
v8.10.0-rc2
v8.10.6-beta2
v8.11
v8.11.0
v8.11.0-rc1
v8.12.0
v8.12.0-rc1
v8.13.0
v8.13.0-pre1
v8.13.0-rc1
v8.13.0-rc2
v8.14.0
v8.14.0-rc1
v8.15.0
v8.15.0-rc2
v8.16.0
v8.16.0-rc1
v8.16.0-rc2
v8.17.0
v8.17.0-rc1
v8.17.0-test1
v8.17.0-test2
v8.17.0-test3
v8.17.0-test4
v8.18.0
v8.18.0-alpha1
v8.18.0-alpha2
v8.18.0-rc1
v8.18.0-rc2
v8.18.0-rc3
v8.2.2
v8.3.0
v8.5.1
v8.5.2
v8.5.3
v8.6.0
v8.6.0-alpha1
v8.6.0-alpha2
v8.6.0-beta1
v8.6.0-beta2
v8.7.0
v8.7.0-alpha2
v8.7.0-rc1
v8.7.0-rc2
v8.7.0-rc3
v8.8.0
v8.8.0-rc1
v8.8.0-rc2
v8.8.0-rc3
v8.9.0
v8.9.0-alpha1
v8.9.0-beta1
v8.9.0-beta2
v8.9.0-rc1
v8.9.0-rc2
v8.9.0-rc3
v8.9.0-rc4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-2913.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "81264585116533091837063788852293356148",
            "length": 775
        },
        "id": "CVE-2026-2913-5a11eaa3",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/libvips/libvips/commit/a56feecbe9ed66521d9647ec9fbcd2546eccd7ee",
        "target": {
            "file": "libvips/iofuncs/source.c",
            "function": "vips_source_read_to_memory"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "279356752735390688259417901222994911966",
            "length": 574
        },
        "id": "CVE-2026-2913-7ef49fc9",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/libvips/libvips/commit/a56feecbe9ed66521d9647ec9fbcd2546eccd7ee",
        "target": {
            "file": "libvips/iofuncs/source.c",
            "function": "vips_source_sniff_at_most"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "291448142552276877238239624487094499721",
                "277299268939537619061950602027585820324",
                "57889987333450730656555089459468282285",
                "186642217395441230341228737770801529885",
                "127923444120314266074828930554756515529",
                "31840049729374283735286227556657049616",
                "40021833950460327588074593176553216811",
                "277477501770652099506644695600975927493",
                "187344673546717005577755839519469378636",
                "97492122235911535734619043184465836729",
                "167413512332663410538673819788118789172",
                "299456589952915040149822499343749301177",
                "10724964163555143445057729214951748917",
                "91032309382667330543825027952811401080",
                "1409473997676061592705228740946968134"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-2913-86b7a855",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/libvips/libvips/commit/a56feecbe9ed66521d9647ec9fbcd2546eccd7ee",
        "target": {
            "file": "libvips/iofuncs/source.c"
        }
    }
]
vanir_signatures_modified
"2026-08-12T15:32:15Z"